Microsoft GDI+ PNG文件整数值溢出远程代码执行漏洞 CVE-2009-3126 CNNVD-200910-234

9.3 AV AC AU C I A
发布: 2009-10-14
修订: 2023-12-07

GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 和 SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1和SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold 和SP3, Office Excel Viewer 2003 Gold和SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1,以及SP2, Word的微软Office文件格式兼容套装,Excel,和PowerPoint 2007 文件格式SP1和SP2,Expression Web, Expression Web 2, Groove 2007 Gold和SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2和SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold以及SP1,和Forefront Client Security 1.0版本中存在整数值溢出。远程攻击者可以借助一个特制的PNG图像文件,执行任意代码。该漏洞又称\"GDI+ PNG 整数值溢出漏洞\"。

0%
暂无可用Exp或PoC
当前有58条受影响产品信息